logo

Malicious npm Packages Harvest Crypto Keys, CI Secrets, and API Tokens

ID: d1860435-7b8a-5053-bd31-e274bf859967

STIX ID: report--d1860435-7b8a-5053-bd31-e274bf859967

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-02-23

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Researchers disclosed an active supply-chain worm campaign called SANDWORM_MODE that uses at least 19 malicious npm packages, a weaponized GitHub Action, and an MCP injection module to harvest developer credentials, SSH keys, cloud/LLM API keys, and cryptocurrency keys while self-propagating via stolen npm and GitHub identities; the malware includes a delayed second stage, polymorphic evasion capabilities, and an optional destructive wiper. Immediate remediation recommended: remove affected packages, rotate tokens and CI secrets, and audit package.json, lockfiles, and .github/workflows for unauthorized changes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.